Cloud Atlas is a cyber-espionage malware campaign and implant set reported by Kaspersky GReAT in December 2014 and assessed as a likely resurgence or rebirth of RedOctober based on strong overlaps in targeting, lure themes, malware architecture, LZMA implementation, shellcode markers, compiler metadata, and overlapping victims. It was observed in targeted attacks beginning in August 2014 using spear-phishing documents exploiting a variation of CVE-2012-0158, with lure filenames including "Diplomatic Car for Sale.doc," "FT – Ukraine Russia’s new art of war.doc," and "Катастрофа малайзийского лайнера.doc."
The infection chain described by Kaspersky used a malicious Office document that wrote an encrypted VBScript to disk rather than directly dropping a PE backdoor. The VBScript then dropped two files: a polymorphically generated loader DLL and an encrypted payload, with each payload encrypted using a unique key. Persistence was established via the Run registry key by creating the value "bookstore" under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run to execute "regsvr32 %path%\ctfmonrn.dll /s" at boot. Reported DLL names included bicorporate.dll, fundamentive.dll, papersaving.dll, previliges.dll, and steinheimman.dll; reported payload names included steinheimman, papersaving, previliges, fundamentive, bicorporate, miditiming, damnatorily, munnopsis, arzner, and redtailed. One cited sample was qPd0aKJu.vbs with MD5 E211C2BAD9A83A6A4247EC3959E2A730, which dropped payload "bicorporate" and loader "ctfmonrn.dll."
Cloud Atlas used an unusual command-and-control mechanism over HTTPS and WebDAV by abusing free CloudMe accounts at cloudme.com. The malware contained an encrypted configuration block with a WebDAV URL, username, password, and folder paths for modules and exfiltrated data. Each observed malware set communicated with a different CloudMe account. The implants uploaded and downloaded encrypted C2 data through CloudMe folders and stored victim data there, including system information, running processes, and the current username. Exfiltrated data was compressed with LZMA and encrypted with AES.
Victimology reported by Kaspersky Security Network placed the top affected countries as Russia, Kazakhstan, Belarus, India, and the Czech Republic, with Russia and Kazakhstan especially prominent. Separate reporting cited in the provided content states that agriculture, government, and transport entities in Donetsk, Luhansk, and Crimea were targeted with novel surveillance malware, and that high-profile organizations in those regions were subjected to Cloud Atlas cyberespionage attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In August 2014, some of our users observed targeted attacks with a variation of CVE-2012-0158 and an unusual set of malware. | In August 2014, some of our users observed targeted attacks with a variation of CVE-2012-0158 and an unusual set of malware... The Cloud Atlas implants utilize a rather unusual C&C mechanism.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In August 2014, some of our users observed targeted attacks with a variation of CVE-2012-0158 and an unusual set of malware... The Cloud Atlas implants utilize a rather unusual C&C mechanism.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
In August 2014, some of our users observed targeted attacks with a variation of CVE-2012-0158... Some of the filenames used in the attacks included: 'FT – Ukraine Russia’s new art of war.doc' ... 'Diplomatic Car for Sale.doc' ... At least one of them immediately reminded us of RedOctober, which used a very similarly named spearphish: 'Diplomatic Car for Sale.doc'.
Perhaps the most unusual fact was that the Microsoft Office exploit didn’t directly write a Windows PE backdoor on disk. Instead, it writes an encrypted Visual Basic Script and runs it.
In August 2014, some of our users observed targeted attacks with a variation of CVE-2012-0158... Perhaps the most unusual fact was that the Microsoft Office exploit didn’t directly write a Windows PE backdoor on disk. Instead, it writes an encrypted Visual Basic Script and runs it.
All the malware samples we’ve seen communicate via HTTPS and WebDav with the same server “cloudme.com”, a cloud services provider... The attackers upload data to the account... In turn, the malware uploads the replies back to the server via the same mechanism.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud Atlas is a cyberespionage malware used to conduct surveillance and intelligence gathering operations against targeted organizations.
A cyber-espionage malware toolkit delivered via spearphishing Office documents exploiting CVE-2012-0158. It drops an encrypted VBScript, a polymorphic loader DLL, and an encrypted payload, persists via a Run registry key using regsvr32, and communicates with C2 over HTTPS/WebDAV through abused CloudMe accounts. It compresses data with LZMA and encrypts communications/data with AES.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.